FortinetãFortiSandboxã¨FortiAuthenticatorã®é大ãªRCEèå¼±æ§ã«ã¤ãã¦è¦åï¼CVE-2026-44277ãCVE-2026-26083ï¼ BleepingComputer â May 12, 2026 Fortinetã¯12æ¥ãFortiAuthenticatorã¨FortiSandboxã«åå¨ããé大ãªèå¼±æ§2ä»¶ã«ã¤ãã¦ã»ãã¥ãªãã£ã¢ãããã¼ãããªãªã¼ã¹ããã 1ä»¶ç®ã®èå¼±æ§ï¼CVE-2026-44277ï¼ã¯ãIDã»ã¢ã¯ã»ã¹ç®¡çï¼IAMï¼ã½ãªã¥ã¼ã·ã§ã³ã®FortiAuthenticatorã«å½±é¿ãä¸ãããã®ããã¼ã¸ã§ã³6.5.7ã6.6.9ãããã³8.0.3ã§ä¿®æ£ããã¦ãããã¢ããã¤ã¶ãªã«ã¯ãFortiAuthenticatorã«ãããä¸é©åãªã¢ã¯ã»ã¹å¶å¾¡ã®èå¼±æ§ï¼CWE-284ï¼ã«ãããèªè¨¼ããã¦ããªãæ»æè ãç´°å·¥ããããªã¯ã¨ã¹ããä»ãã¦ä¸æ£ãªã³ã¼
NIST is changing the way it handles cybersecurity vulnerabilities and exposures, or CVEs, listed in its National Vulnerability Database (NVD). In the past, NISTâs NVD program aimed to analyze all CVEs to add details â such as severity scores and product lists â that help cybersecurity professionals prioritize and mitigate vulnerabilities. Going forward, NIST will add details, or âenrich,â those CV
ç±³æ¿åºæ©é¢ãä¸çã®ä¸»è¦ã½ããã¦ã¨ã¢ã«é¢ããèå¼±æ§ããã¹ã¦åæããè©ä¾¡ããã®ãåãããããç±³æ°èã¢ã³ã½ãããã¯ã®ãMythosï¼ãã¥ãã¹ï¼ãã¨ãã£ãé«åº¦ãªäººå·¥ç¥è½ï¼AIï¼ã®ç»å ´ã§ãæ¥å¢ããèå¼±æ§ã®æ¤ç¥ã«åæã追ãã¤ããªã宿 ãåæ ãããèå¼±æ§ã®åæãè©ä¾¡ãææããç±³å½ç«æ¨æºæè¡ç ç©¶æï¼NISTï¼ããèå¼±æ§ã«é¢ããåæã«ã¤ãã¦ãç·æ¥æ§ãé«ãæ¡ä»¶ã«éå®ããæ¹éã示ãããä¸çã®ä¼æ¥ãç ç©¶è ããå ±åãå
Japan Vulnerability Notesï¼JVNï¼ã¯4æ3æ¥ãæ¥æ¬é»æ°ï¼NECï¼è£½ã®è¤æ°ã®Wi-Fiã«ã¼ã¿ã¼ã«é¢ããèå¼±æ§æ å ±ãå ¬éããã èå¼±æ§ã®æ¦è¦ã¨æ³å®ãããå½±é¿ã¯ããããã以ä¸ã®ã¨ããã âèå¼±æ§ã®æ¦è¦ ã»æ¨©éãã§ãã¯ã®æ¬ å¦ï¼CVE-2026-4309ï¼ ã»ãã¹ãã©ãã¼ãµã«ï¼CVE-2026-4619ï¼ ã»OSã³ãã³ãã¤ã³ã¸ã§ã¯ã·ã§ã³ï¼CVE-2026-4620ï¼CVE-2026-4622ï¼ ã»ã»ãã¥ãªãã£ä¸åé¡ã®ããé ãæ©è½ï¼CVE-2026-4621ï¼ âæ³å®ãããå½±é¿ï¼ä¸ä¾ï¼ ã»è£ ç½®åºæã®æ å ±ãåå¾ãããçµæã¨ãã¦è¨å®ã夿´ãããï¼CVE-2026-4309ï¼ ã»ä»»æã®ãã¡ã¤ã«ã䏿¸ããããï¼CVE-2026-4619ï¼ ã»ä»»æã®OSã³ãã³ããå®è¡ãããï¼CVE-2026-4620ï¼CVE-2026-4622ï¼ ã»telnetãµã¼ãã¹ãæå¹åãããï¼CVE-2026
Active Directoryãã¾ãè¦ã¤ãã£ãèå¼±æ§ã¨èªè¨¼åé¡ã対çã¯ï¼ï¼Microsoft Azureææ°æ©è½ãã©ãã¼ã¢ããï¼227ï¼ Microsoftã®ãActive Directoryãã«é¢ãã¦ãå度æ°ããªè¤æ°ãã§ã¼ãºãæã¤èå¼±æ§å¯¾çãè¦ã¤ããã¾ãããããã§ã»ãã¥ãªãã£å¼·åã䏿°ã«é²ããã¨ãæ å ±ã·ã¹ãã ã®å©ç¨ä¸å¯ã¨ãã£ãé害ã«ã¤ãªããæããããã¾ãã Microsoft Azureææ°æ©è½ãã©ãã¼ã¢ãã Active Directoryã§å度è¦ã¤ãã£ãæ°ããªèå¼±æ§ã¨èªè¨¼ã®åé¡ã¨ã¯ 以åãMicrosoftã®ãActive Directoryãã«é¢ããèå¼±ï¼ãããããï¼æ§ã¨èªè¨¼ã®åé¡ã«é¢ãã¦ããè¤æ°ãã§ã¼ãºã§æãç«ã¤ãActive Directoryã®èå¼±æ§å¯¾çãã¨ã¯ââãã®æå³ã¯ï¼ã詳細ã¯ï¼ããæ°ãã«è¦ã¤ãã£ãActive Directoryã®èå¼±æ§å¯¾çã¨èªè¨¼åé¡ããã®å¯¾å¦æ¹æ³ã¯
ã¦ã§ããµã¼ããNGINXãã«ããã¦ä¸éè æ»æã«ããå¿çãæ¹ãããããããããããèå¼±æ§ã夿ãããåç¨çããªã¼ãã³ã½ã¼ã¹çã®ããããå½±é¿ãåããã TLSã§ä¿è·ããã䏿µãµã¼ãã¸ãããã·ãè¨å®ããå ´åã«ãä¸éè æ»æï¼MITMæ»æï¼ã§å¿çã¸å¹³æãã¼ã¿ãæ³¨å ¥ãããããããããèå¼±æ§ãCVE-2026-1642ãã確èªãããã ä¿¡é ¼ããããã¼ã¿ã¨ä¿¡é ¼ããã¦ããªãå¤é¨ãã¼ã¿ãé©åã«åºå¥ããåãå ¥ãã¦ãã¾ããã¨ã«èµ·å ãæ¹ããããããã¼ã¿ããã®ã¾ã¾ã¯ã©ã¤ã¢ã³ãã¸éä¿¡ãããããããããã å ±éèå¼±æ§è©ä¾¡ã·ã¹ãã ãCVSSv4.0ãã®ãã¼ã¹ã¹ã³ã¢ã¯ã8.2ããéè¦åº¦ã¯4段éä¸ãä¸ãã2çªç®ã«ããããé«ï¼Highï¼ãã¨ã¬ã¼ãã£ã³ã°ããã¦ããããCVSSv3.1ãã§ã¯ãã¼ã¹ã¹ã³ã¢ãã5.9ããéè¦åº¦ã¯ãä¸ï¼Mediumï¼ãã¨ãããã F5ã§ã¯ãåèå¼±æ§ã¸å¯¾å¦ãããNGINX Open Source 1.29.
GCVE initiativeã¯2026å¹´1æ7æ¥ï¼ç¾å°æéï¼ãæ°ããªå ¬éèå¼±ï¼ãããããï¼æ§å©è¨ãã¼ã¿ãã¼ã¹ãdb.gcve.euãã®å ¬éãçºè¡¨ããã ãã®åºç¤ã¯èª°ã§ãç¡åã§å©ç¨ã§ããä¸çä¸ã§å ¬éããã¦ããèå¼±æ§æ å ±ãçµ±åçã«åç §ã§ããå ´ãæä¾ãããç±³å½ã®èå¼±æ§æ å ±ãã¼ã¿ãã¼ã¹ï¼CVEï¼ã«å¼·ãä¾åããä½å¶ã®ç·©åããã»ãã¥ãªãã£å¯¾å¿ã«æºããçµç¹ãç ç©¶è ãæ å ±ãè¦å¤±ããã«å ¨ä½åãææ¡ããããããçããããã CVEã¨ä½ãéãï¼ãç¡åã§å©ç¨ã§ããæ°æä»£ã®èå¼±æ§å ±æã¢ãã« db.gcve.euã¯25以ä¸ã®å ¬éæ å ±æºããèå¼±æ§å©è¨ãåéããèå¥åãå å®¹ãæ´çããå½¢ã§æç¤ºãããGCVEã«åºã¥ãçªå·ä»ä¸ä¸»ä½ãçºè¡ããæ å ±ãèªç¶ã«åãè¾¼ã¾ãã¦ãããæ¤ç´¢ãåæã«é©ããæ§é åãã¼ã¿ã¨ãã¦æ±ããç¹ãç¹å¾´ã ã忣ãã¦åå¨ãã¦ããæ å ±ã俯ç°ã§ããç¶æ³çè§£ã®è² æ 軽æ¸ã«ã¤ãªããã åºç¤æè¡ã«ã¯ããªã¼ãã³ã½ã¼ã¹ã®ãvu
注éï¼è¿½è¨ãã¹ãæ å ±ãããå ´åã«ã¯ããã®é½åº¦ãã®ãã¼ã¸ãæ´æ°ããäºå®ã§ãã æ¦è¦ Fortinet社ãæä¾ããFortiOSãFortiWebãFortiProxyãFortiSwitchManagerãããã³FortiWebã«é¢ããèå¼±æ§æ å ±ãå ¬éããã¾ããã ãããã®è£½åã«ããã¦ããã¸ã¿ã«ç½²åã®ä¸é©åãªæ¤è¨¼ã®èå¼±æ§ï¼CVE-2025-59718ãCVE-2025-59719ï¼ã確èªããã¦ãã¾ãã æ¬èå¼±æ§ãæªç¨ãããå ´åãèªè¨¼ããã¦ããªãé éã®ç¬¬ä¸è ã«ãã£ã¦ãèªè¨¼ãåé¿ãããå¯è½æ§ãããã¾ãã ãããã®èå¼±æ§ã«é¢ãã製åéçºè ã«ããCVSSè©ä¾¡ã«ããã¦ãæ»æã³ã¼ããåå¨ãã¦ããã¨ã®è©ä¾¡ãããã¦ãã¾ãã ä»å¾è¢«å®³ãæ¡å¤§ããæããããããã製åéçºè ãå ¬è¡¨ãã¦ããæé ã«å¾ãããã¼ã¸ã§ã³ã¢ãããã¦ãã ããã å½±é¿ãåããã·ã¹ãã FortiOS 7.6.0 ãã 7.6.3 FortiOS
ãã¤ã¯ãã½ããã® Microsoft Windows 10ãWindows 11ãWindows Server ã«ã¯ãWindows SMB ã¯ã©ã¤ã¢ã³ãã«ä¸åããããããæ¨©éãææ ¼ãããèå¼±æ§ãåå¨ãã¾ãã CVSS v3 ã«ããæ·±å»åº¦ åºæ¬å¤: 8.8 (éè¦) [ãã®ä»] æ»æå åºå: ãããã¯ã¼ã¯ æ»ææ¡ä»¶ã®è¤éã: ä½ æ»æã«å¿ è¦ãªç¹æ¨©ã¬ãã«: ä½ å©ç¨è ã®é¢ä¸: ä¸è¦ å½±é¿ã®æ³å®ç¯å²: 夿´ãªã æ©å¯æ§ã¸ã®å½±é¿(C): é« å®å ¨æ§ã¸ã®å½±é¿(I): é« å¯ç¨æ§ã¸ã®å½±é¿(A): é« ãã¤ã¯ãã½ãã Microsoft Windows 10 for 32-bit Systems Microsoft Windows 10 for x64-based Systems Microsoft Windows 10 Version 1607 for 32-bit Systems Microsof
Commercial support for versions past the Maintenance LTS phase is available through our OpenJS Ecosystem Sustainability Program partners Security releases available Updates are now available for the 25.x, 24.x, 22.x, and 20.x Node.js release lines to address: 3 high severity issues. 4 medium severity issues. 1 low severity issue. This security release includes the following dependency updates to a
IBMãæä¾ããAPI管çãã©ãããã©ã¼ã ãIBM API Connectãã«æ·±å»ãªèå¼±æ§ã夿ãããæ«å®çãªä¿®æ£ããã°ã©ã ãæä¾ããã¦ããã å社ã¯ãç¾å°æé2025å¹´12æ17æ¥ã«ã»ãã¥ãªãã£ã¢ããã¤ã¶ãªãå ¬éããLinuxåãã«æä¾ããã¦ãããIBM API Connectãã«ç¢ºèªãããèªè¨¼åé¿ã®èå¼±æ§ãCVE-2025-13915ãã«ã¤ãã¦æããã«ããã èå¼±æ§ãæªç¨ããã¨ãèªè¨¼ãå¿ è¦ã¨ãããã¨ãªããªã¢ã¼ãããã®ã¢ã¯ã»ã¹ãå¯è½ã¨ãªããå é¨ãã¹ãã«ããåèå¼±æ§ãçºè¦ããã¨ããã å ±éèå¼±æ§è©ä¾¡ã·ã¹ãã ãCVSSv3.1ãã®ãã¼ã¹ã¹ã³ã¢ã¯ã9.8ããéè¦åº¦ã¯4段éä¸ãã£ã¨ãé«ããã¯ãªãã£ã«ã«ï¼Criticalï¼ãã¨ã¬ã¼ãã£ã³ã°ããã¦ããã ãIBM API Connect 10.0.11ãããã³ãå10.0.8.0ããããå10.0.8.5ãã¾ã§ãåèå¼±æ§ã®å½±é¿ãåããã å社ã§ã¯åã
JSer.info #759 - Next.js 16.1ããªãªã¼ã¹ããã¾ããã Next.js 16.1 | Next.js Turbopackã®File System Cacheãnext devã§ãå©ç¨ã§ããããã«ãªããéçºãµã¼ãã¼åèµ·åæã®ã³ã³ãã¤ã«æéãç縮ããã¦ãã¾ããã¾ããNode.jsãããã¬ã¼ãç°¡åã«æå¹åã§ããnext dev --inspectã³ãã³ããããã¼ã¸ã§ã³ã¢ããã°ã¬ã¼ããè£å©ããnext upgradeã³ãã³ãã追å ããã¦ãã¾ããå®é¨çæ©è½ã¨ãã¦Bundle Analyzerã追å ããã¦ãã¾ãã Vue 3.6.0 beta 1ããªãªã¼ã¹ããã¾ããã Release v3.6.0-beta.1 · vuejs/core Vapor Modeããã¼ã¿çã¨ãã¦è¿½å ããã¦ãã¾ããVapor Modeã¯ä»®æ³DOMã使ããªãã³ã³ãã¤ã«æ¦ç¥ã§ããã³ãã«ãµã¤ãºåæ¸ã¨ããã©
èªå·±ç´¹ä» çæ§ãã¯ããã¾ãã¦ã2025å¹´11æã«MBSDã«å ¥ç¤¾ããæµ¦ç°ã¨ç³ãã¾ãã ãã®åº¦ãã©ã³ãµã ã¦ã§ã¢ã®ãã³ã¹ãªã¼ã¬ãã¼ããã©ã³ãµã ã¦ã§ã¢ããããå¤é·å³ã(ç¥ã£ã¦ãã人ã¯ç¥ã£ã¦ãããä¾ã®ã¯ãªã¢ãã¡ã¤ã«ã«ãªã£ã¦ããããããã¤ï¼ãçºåãã¦ãããã¨ã§ã馴æã¿ã®ãCyber Intelligence Groupï¼éç§°CIGãã¼ã ï¼ã«åå ãããªãµã¼ãã£ã¼ã¨ãã¦æ´»åããã¦ããã ããã¨ã«ãªãã¾ããã ã¾ããCIGã¯ããã«ã¦ã¨ã¢ã®æç§æ¸ãã§ç¥ãããåå·ãããçãããã¼ã ã§ãããã¾ãã ç§ã¯ãåè·ã§ã¯å®å ¬åºã§ç¯ç½ªææ»ã«é¢ãã£ã¦ããã主ã«ãµã¤ãã¼ç¯ç½ªã®èª¿æ»ç ç©¶ããã¸ã¿ã«ãã©ã¬ã³ã¸ãã¯ãè¡ã£ã¦ãã¾ããã ããã«ãã®åã¯ããã°ã©ãã¼ã¨ãã¦éçºã«æºãã£ã¦ãã¾ããããã³ã¼ããæ¸ããã¨ã好ãã§ãä»ã§ãæãåããã¦ããæéããã¡ã°ãè½ã¡çãã¾ãã ã»ãã¥ãªãã£é¢é£ã§ã¯ãæ¥ã ãã£ã¦ããæ»ææ å ±ã®åéåæãããã«ã¦ã§ã¢è§£
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}